Crisis Trojan Makes Its Way onto Virtual Machines

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
The Windows version of the Crisis Trojan is able to sneak onto VMware implementations, making it possibly the first malware to target such virtual machines. It also has found a way to spread to Windows Mobile devices.

"Many threats will terminate themselves when they find a virtual machine monitoring application, such as VMware, to avoid being analyzed, so this may be the next leap forward for malware authors," wrote Takashi Katsuki of Symantec in a blog post.

Samples of Crisis, also called Morcut, were first discovered about a month ago targeting Mac machines running various versions of OS X. The Trojan spies on users by intercepting e-mail and instant messenger exchanges and eavesdropping on webcam conversations. Launching as a Java archive (JAR) file made to look like an Adobe Flash Installer, Crisis scans an infected machine and drops an OS-specific executable to open a backdoor and monitor activity.

http://threatpost.com/en_us/blogs/crisis-trojan-makes-its-way-virtual-machines-082112
 
[h=1]Crisis Believed to be First Malware Infecting Virtual Machines[/h]http://www.tomshardware.com/news/security-crisis-malware-trojan,17141.html#xtor=RSS-181
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top